GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
2,891
Erlang
24
GitHub Actions
39
Go
2,240
Maven
2,698
npm
2,899
NuGet
500
pip
2,728
Pub
5
RubyGems
364
Rust
889
Swift
19
Unreviewed advisories
All unreviewed
5,000+
21 advisories
Filter by severity
NYUCCL psiTurk IS vulnerable to Improper Neutralization of Special Elements
High
CVE-2021-4315
was published
for
psiTurk
(pip)
Jan 29, 2023
OctoPrint vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
High
CVE-2023-41047
was published
for
OctoPrint
(pip)
Oct 10, 2023
Ansible template injection vulnerability
Moderate
CVE-2023-5764
was published
for
ansible-core
(pip)
Dec 13, 2023
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
High
CVE-2024-37301
was published
for
document-merge-service
(pip)
Jun 11, 2024
Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine
High
CVE-2024-45053
was published
for
ethyca-fides
(pip)
Sep 4, 2024
changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
Critical
CVE-2024-32651
was published
for
changedetection.io
(pip)
Oct 15, 2024
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Moderate
CVE-2025-27516
was published
for
Jinja2
(pip)
Mar 5, 2025
Spacy-LLM Server-Side Template Injection (SSTI) vulnerability
High
CVE-2025-25362
was published
for
spacy-llm
(pip)
Mar 5, 2025
Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating
Moderate
CVE-2025-49142
was published
for
nautobot
(pip)
Jun 10, 2025
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
High
CVE-2025-65106
was published
for
langchain-core
(pip)
Nov 20, 2025
datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler
Low
CVE-2026-2969
was published
for
datapizza-ai-core
(pip)
Feb 23, 2026
Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection
Critical
CVE-2026-27641
was published
for
flask-reuploaded
(pip)
Feb 25, 2026
dynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja Resolver
High
CVE-2026-33154
was published
for
dynaconf
(pip)
Mar 18, 2026
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
High
CVE-2026-34172
was published
for
giskard-agents
(pip)
Mar 27, 2026
BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation
High
CVE-2026-35044
was published
for
bentoml
(pip)
Apr 3, 2026
LangChain has incomplete f-string validation in prompt templates
Moderate
CVE-2026-40087
was published
for
langchain-core
(pip)
Apr 8, 2026
Giskard has Unsandboxed Jinja2 Template Rendering in ConformityCheck
Moderate
CVE-2026-40320
was published
for
giskard-checks
(pip)
Apr 14, 2026
Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates
Moderate
CVE-2026-40602
was published
for
homeassistant-cli
(pip)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API